A

Regulatory Compliance Advisory

We translate regulatory obligations — GDPR, FCA and PRA handbook requirements, and relevant cross-border rules — into practical, operational programmes. This includes gap analysis against current practice, remediation planning, policy drafting, and preparation of evidence packs for supervisory review.

Engagements typically begin with a diagnostic phase before moving into structured remediation, with a partner available throughout for direct regulator liaison support.

Delivered
Gap analysis, remediation roadmap, policy suite, regulator-ready evidence pack
Typical Engagement
8–14 weeks
B

IT Risk Assessment

A structured evaluation of technology risk across infrastructure, third-party dependencies, access controls and data handling practices. We benchmark findings against recognised frameworks and produce a prioritised remediation register that your risk committee can act on directly.

Assessments are scoped to reflect your operating model, with particular attention to outsourced and cloud-hosted components common in financial services technology estates.

Delivered
Risk register, control-maturity scoring, board-level summary report
Typical Engagement
4–8 weeks
C

ISO/SOC Audit Preparation

End-to-end readiness support for ISO 27001 certification and SOC 2 Type I or Type II attestation. We conduct pre-audit control testing, close evidentiary gaps, and prepare your team for auditor interviews, so that certification proceeds without surprises.

Where an organisation already holds certification, we also support surveillance audits and scope expansions as the business grows.

Delivered
Control mapping, internal audit, evidence repository, mock audit interviews
Typical Engagement
10–16 weeks
D

Governance Framework Design

We design IT governance structures — committee charters, reporting lines, policy hierarchies and decision rights — that hold up under regulatory scrutiny and scale as your organisation grows. This work is often the foundation on which our other three services are built.

Deliverables are drafted for direct board and executive committee adoption, with supporting materials to brief non-technical stakeholders.

Delivered
Governance charter, policy hierarchy, RACI model, board reporting templates
Typical Engagement
6–10 weeks

Not sure where to start?

Most engagements begin with a short scoping conversation. We will recommend the right service, sequencing, and timeline for your organisation.

Speak With a Partner